Victims Continue to Fall: Recognising Phishing Signs for Bank Customers
Bank customers must remain vigilant against the surge in cybercrime amid rapid digital service growth. One of the most common tactics used by perpetrators is phishing, targeting mobile banking users, social media, email, and digital wallet apps.
To date, many people remain phishing victims, resulting in not only loss of account access and personal data but also financial losses as funds are drained from their accounts after falling for fake links or suspicious messages.
Therefore, understanding phishing and other digital scams is crucial for protecting oneself from cybercrime.
What is Phishing?
Phishing is a cyber scam where perpetrators impersonate trusted entities to steal sensitive information such as passwords, PINs, OTP codes, credit card numbers, and bank account details.
Perpetrators typically send emails, SMS, WhatsApp messages, or fake links mimicking official bank, marketplace, or company websites. When victims enter personal data, it is immediately stolen.
Recently, scammers have become more sophisticated, using AI-powered voice calls with fake visuals resembling prominent figures to convince victims to transfer money.
Phishing generally operates in three main stages:
- Creating the bait: Scammers send seemingly official messages, such as:
‘Your account will be blocked’
‘You’ve won a prize’
‘Verify your account now’
‘Package delivery failed’
Victims are directed to fake websites where the links resemble legitimate domains. For example: bri.co.id (legitimate) vs bank-bri.com (fake).
Victim data is stolen: When entering usernames, passwords, PINs, or OTPs, the data is stored on the scammer’s server.
Common types of phishing include:
Email phishing: Scammers send fake emails appearing to be from banks or companies, often containing links that steal bank account details.
SMS phishing: Crimes conducted via SMS or chat apps like WhatsApp and Telegram.
Vishing: Phone calls where scammers pose as bank customer service or official representatives, or even AI-generated video calls.
Spear phishing: Targeted attacks using victims’ personal data to appear more convincing.
How to detect phishing?
Several signs can help identify phishing early:
- Carefully check website URLs. Phishing sites often use extra letters, strange symbols, similar domains, or misspellings.
Example:
Legitimate: bri.co.id
Fake: bank–bri.com
- Urgent or threatening language intended to panic victims into acting hastily. Phishing messages often include:
‘Click now immediately’
‘Account will be blocked in 1 hour’
‘Verify now’
Requests for sensitive data. Remember, banks never ask for passwords, PINs, OTPs, or credit card CVVs. Any such request is almost certainly phishing.
Frequent spelling errors, poor grammar, messy design, or overly polished layouts in emails or messages.
Tips to avoid phishing:
Do not click links without verifying they come from a legitimate source.
Check official websites.
Never share passwords, PINs, or OTPs.
Regularly change passwords and PINs.
Most importantly, educate yourself and family, as many phishing victims result from low digital literacy. Education is the primary defence against online scams.
1,000 Reports Daily
The Financial Services Authority (OJK) revealed that financial scams remain rampant in Indonesia.
Through the Indonesia Anti Scam Centre (IASC), OJK collected 548,093 reports. Of these, 268,989 were submitted by businesses and 279,104 directly by the public to IASC.
OJK Executive Head for Financial Business Conduct, Education, and Consumer Protection Dicky Kartiyono stated that 932,138 accounts were verified, with 485,758 blocked. Additionally, 106,477 phone numbers were blocked related to scams.
OJK acknowledged challenges in handling scams, including a surge in complaints reaching around 1,000 reports per day — three to four times higher than in other countries.
BRI IT Director Saladin D Effendi said the most common scam tactic is spreading fake links via SMS, email, or messaging apps. These links mimic official appearances to steal sensitive data like user IDs, PINs, passwords, and OTPs through social engineering.
‘BRI urges the public not to trust suspicious links. Always access services through BRI’s official channels and never share personal data with anyone,’ he said in a press release dated Friday, 29 May 2026.